ISO 42001 requirements: clauses and Annex A controls
To get ISO 42001 certified you have to meet its requirements — but the standard's language can be dense. This guide translates what ISO/IEC 42001 actually asks for: the management-system clauses and the Annex A controls, in plain English. It's part of our guide to ISO 42001 certification.
AramGRC Team·ISO 42001 & Assurance·September 10, 2026·8 min read
The structure of ISO 42001
ISO 42001 uses the same harmonised high-level structure as ISO 27001 and ISO 9001, so its requirements sit in clauses 4 to 10. Clauses 1–3 cover scope, references and terms; the auditable requirements begin at clause 4.
The management-system clauses (4–10)
Clause 4 — Context: define the scope of your AI management system and understand the internal and external issues and interested parties.
Clause 5 — Leadership: top-management ownership, an AI policy, and clear roles and responsibilities.
Clause 6 — Planning: AI risk assessment and treatment, AI impact assessment, and objectives.
Clause 7 — Support: resources, competence, awareness, communication and documented information.
Clause 8 — Operation: putting the controls into practice across the AI lifecycle, including the risk and impact assessments.
Clause 10 — Improvement: corrective action and continual improvement.
The Annex A controls
Alongside the clauses, Annex A provides a reference set of AI-specific controls you select and implement based on your risks. They span areas such as AI policies; internal organisation and roles; resources for AI systems (data, tooling, human oversight); AI impact assessment; the AI system lifecycle from design to retirement; data management and quality; information and transparency for users; and the responsible use and third-party or supplier management of AI. You record which controls apply, and why, in a Statement of Applicability.
AI impact assessment: the requirement people miss
A defining requirement of ISO 42001 is the AI system impact assessment — evaluating the consequences of an AI system on individuals and groups, not just on the organisation. This, alongside the risk assessment, is where most of the real work sits, and where auditors look closely.
How the requirements map to certification
Meeting these requirements is exactly what a certification audit checks — Stage 1 reviews your documentation and readiness, Stage 2 tests that the system operates in practice. See how to get ISO 42001 certified and work through the ISO 42001 checklist.
How AramGRC helps
AramGRC's ISO/IEC 42001 gap assessment scores your organisation against every clause and Annex A control and hands you a prioritised roadmap to close the gaps.
Frequently asked questions
What are the requirements of ISO 42001?+
ISO 42001's requirements sit in clauses 4–10 (context, leadership, planning, support, operation, performance evaluation, improvement), plus a set of AI-specific controls in Annex A that you select based on your risks.
What is Annex A in ISO 42001?+
Annex A is the standard's reference catalogue of AI-specific controls — covering AI policy, roles, impact assessment, the AI lifecycle, data, transparency and third-party AI — that you apply and record in a Statement of Applicability.
What is an AI impact assessment?+
An assessment of how an AI system affects individuals and groups. It's a defining ISO 42001 requirement and a key focus of certification audits.
How many controls does ISO 42001 have?+
Annex A provides a catalogue of AI-specific controls grouped into control areas; you apply the ones relevant to your risks and document them in a Statement of Applicability, rather than implementing all of them regardless.